Nss On The System Disk; Security Flag Recommendations - Novell OPEN ENTERPRISE SERVER 2 SP2 Installation Manual

Hide thumbs Also See for OPEN ENTERPRISE SERVER 2 SP2:
Table of Contents

Advertisement

Partition
Other Considerations
to Create
/tmp
Creating this as a separate partition is optional. However, because it is writable by everyone,
best practices suggest creating a separate partition to avoid having someone flood the disk by
accident or on purpose, which impacts system and service stability.
Place application specific files on a separate partition.
If you are building a mail server, note where the mail spools reside because they can grow
quite large, and you need to anticipate this when you are defining partition sizes.

NSS on the System Disk

For OES, Novell Storage Services™ (NSS) volumes can be used only as data volumes, not as
system volumes.
Additionally, they cannot be created as part of the install process.
However, you must consider whether you will be creating them in the future on the storage device
where you are installing Linux. (Creating NSS volumes on storage devices that don't contain Linux
system partitions requires no special handling.)
The default volume manager for Linux POSIX volumes on SUSE Linux is LVM (Linux Volume
Manager). However, NSS volumes cannot be created on devices managed by LVM; they require
EVMS (Enterprise Volume Management System) instead.
IMPORTANT: If you have only a single storage device on the server (such as a single physical disk
or a hardware RAID 1 or RAID 5 device) and you plan to use NSS volumes for storing data, you
must follow the instructions in
Device" on page 211
You must also follow the EVMS setup instructions if you are creating Linux system partitions on
other storage devices that you also want to contain NSS volumes.

Security Flag Recommendations

The following table indicates the recommended security flags for each partition. A question mark
indicates that some software might not work if this flag is set.
Mount Point
/
/var
/tmp
/home
/srv
50
OES 2 SP2: Installation Guide
"Installing with EVMS as the Volume Manager of the System
to partition that storage device before proceeding.
Mount Options
nosuid
nosuid
,
,
?
nosuid
nodev
noexec
nosuid
?,
nodev
?,
noexec
installation)
?,
ro
? (after

Advertisement

Table of Contents
loading

Table of Contents